Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
4.3
CVE-2024-13580
- EPSS 0.02%
- Published 11.03.2025 06:00:08
- Last modified 29.08.2025 16:39:17
The XV Random Quotes WordPress plugin through 1.40 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin reset them via a CSRF attack
7.1
CVE-2024-13574
- EPSS 0.05%
- Published 11.03.2025 06:00:05
- Last modified 29.08.2025 16:39:10
The XV Random Quotes WordPress plugin through 1.40 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
1